WireGuard

How WireGuard works in the privymail.eu VPN: methods, port, key renewal, what the server remembers and how it differs from OpenVPN.

Status: The VPN service is planned for December 2026; details may change before then.

Little code. Fixed methods.

WireGuard is a VPN protocol that makes do with little code and a fixed set of modern cryptographic methods. It is open source and has been part of the Linux kernel since 2020. The privymail.eu VPN speaks it alongside OpenVPN.

Encryption: fixed rather than negotiated

With many older protocols, the two sides negotiate which methods they use. WireGuard prescribes them. A weak setting that someone picks by mistake or forces on a device therefore does not exist. The price: if one of the methods shows a weakness, a new version of the protocol is needed on every device.

TaskMethod
Encrypting the dataChaCha20
Detecting changes to the dataPoly1305
Agreeing keysCurve25519
Hash functionBLAKE2s
Deriving keysHKDF
Securing internal lookup tablesSipHash24

Each device identifies itself with a key pair. The keys for the actual data are created afresh each time a connection is set up and are replaced automatically while it runs (perfect forward secrecy). Anyone who later gets hold of a long-term key cannot read previously captured traffic with it.

The source code is small. Less code means fewer places for errors to hide and less effort for everyone who reviews it.

Speed

WireGuard needs little computing time per packet, spreads the work across several processor cores and sets up a connection with a single exchange, practically without waiting. ChaCha20 is also fast on devices whose processor does not specifically accelerate encryption. On a phone, that is easy on the battery.

How fast a connection actually is also depends on your own line, the route to the VPN server and the upper limit of your plan: at most 10 Mbit/s in the Free plan, at most 1 Gbit/s in the paid plans.

Stability and changing networks

WireGuard works over UDP only; the VPN servers accept it on port 9929. The VPN server recognises your device by its key, not by its address. When your phone switches from Wi-Fi to mobile data, the tunnel therefore carries on without a new connection set-up.

The downside: networks that block UDP or let only web traffic through block WireGuard as well. Obfuscation that disguises the tunnel as other traffic is not part of it. On such networks, OpenVPN over TCP often gets through.

Ease of use

A WireGuard configuration is short: your own key, the VPN server's key and address, plus the address ranges that go through the tunnel. On a computer you import it as a file; on a phone it can also be read in as a QR code. WireGuard apps exist for Windows, macOS, Linux, Android and iOS; some routers support the protocol too. The steps are under Setting up the VPN.

Privacy: what the server remembers

WireGuard encrypts, but it does not conceal who is connected. It is part of the protocol that the VPN server keeps, for each key, which addresses inside the tunnel belong to it, which internet address the last valid packet came from and when keys were last exchanged.

How long such information stays is decided by how the service is run, not by the protocol. In the VPN service, the IP address you connect from sits in volatile memory and is deleted when the session ends. A key management service removes every device from the VPN server's memory that has gone three minutes without a handshake. More under VPN and privacy.

WireGuard or OpenVPN?

FeatureWireGuardOpenVPN
Originyoung, in the Linux kernel since 2020in use since 2001
Encryptionfixed set: ChaCha20, Poly1305, Curve25519negotiated over TLS, depending on the version: ChaCha20-Poly1305 or AES-256-GCM, with old apps AES-256-CBC
TransportUDP only, port 9929UDP or TCP, ports 1194, 1195 and 443
New keys while runningautomaticevery 45 to 75 minutes
Connection set-upone exchange, practically instantseveral steps, can take a few seconds
Changing networkstunnel carries onconnection is usually set up again
Networks that block UDPdoes not get throughoften gets through over TCP
Processor coresuses severaluses one
Size of the source codesmallmany times larger

WireGuard fits if you use a phone or laptop on changing networks and want things to be fast. OpenVPN fits if a network does not let WireGuard through. What neither of them does is listed under VPN security.

WireGuard is a registered trademark of Jason A. Donenfeld.